Question 1 of 30
In a corporate environment, a software development team is integrating a third-party application that requires access to user data stored in Microsoft Graph. The application needs to perform actions such as reading user profiles, sending messages on behalf of users, and accessing calendar events. The team must configure the appropriate API permissions and scopes to ensure that the application functions correctly while adhering to the principle of least privilege. Given this scenario, which combination of permissions and scopes should the team request to achieve the required functionality without over-permissioning?
User.Read, Mail.Send, Calendars.Read
User.Read.All, Mail.Send, Calendars.ReadWrite
User.ReadWrite.All, Mail.Read, Calendars.ReadWrite
User.Read, Mail.ReadWrite, Calendars.ReadWrite

Preparing for Microsoft SC-300 Microsoft Identity and Access Administrator? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free